CommandLine:Add\-Exfiltration* OR CommandLine:Add\-Persistence* OR CommandLine:Add\-RegBackdoor* OR CommandLine:Add\-RemoteRegBackdoor* OR CommandLine:Add\-ScrnSaveBackdoor* OR CommandLine:Check\-VM* OR CommandLine:ConvertTo\-Rc4ByteStream* OR CommandLine:Decrypt\-Hash* OR CommandLine:Disable\-ADIDNSNode* OR CommandLine:Disable\-MachineAccount* OR CommandLine:Do\-Exfiltration* OR CommandLine:Enable\-ADIDNSNode* OR CommandLine:Enable\-MachineAccount* OR CommandLine:Enabled\-DuplicateToken* OR CommandLine:Exploit\-Jboss* OR CommandLine:Export\-ADR* OR CommandLine:Export\-ADRCSV* OR CommandLine:Export\-ADRExcel* OR CommandLine:Export\-ADRHTML* OR CommandLine:Export\-ADRJSON* OR CommandLine:Export\-ADRXML* OR CommandLine:Find\-Fruit* OR CommandLine:Find\-GPOLocation* OR CommandLine:Find\-TrustedDocuments* OR CommandLine:Get\-ADIDNS* OR CommandLine:Get\-ApplicationHost* OR CommandLine:Get\-ChromeDump* OR CommandLine:Get\-ClipboardContents* OR CommandLine:Get\-FoxDump* OR CommandLine:Get\-GPPPassword* OR CommandLine:Get\-IndexedItem* OR CommandLine:Get\-KerberosAESKey* OR CommandLine:Get\-Keystrokes* OR CommandLine:Get\-LSASecret* OR CommandLine:Get\-MachineAccountAttribute* OR CommandLine:Get\-MachineAccountCreator* OR CommandLine:Get\-PassHashes* OR CommandLine:Get\-RegAlwaysInstallElevated* OR CommandLine:Get\-RegAutoLogon* OR CommandLine:Get\-RemoteBootKey* OR CommandLine:Get\-RemoteCachedCredential* OR CommandLine:Get\-RemoteLocalAccountHash* OR CommandLine:Get\-RemoteLSAKey* OR CommandLine:Get\-RemoteMachineAccountHash* OR CommandLine:Get\-RemoteNLKMKey* OR CommandLine:Get\-RickAstley* OR CommandLine:Get\-Screenshot* OR CommandLine:Get\-SecurityPackages* OR CommandLine:Get\-ServiceFilePermission* OR CommandLine:Get\-ServicePermission* OR CommandLine:Get\-ServiceUnquoted* OR CommandLine:Get\-SiteListPassword* OR CommandLine:Get\-System* OR CommandLine:Get\-TimedScreenshot* OR CommandLine:Get\-UnattendedInstallFile* OR CommandLine:Get\-Unconstrained* OR CommandLine:Get\-USBKeystrokes* OR CommandLine:Get\-VaultCredential* OR CommandLine:Get\-VulnAutoRun* OR CommandLine:Get\-VulnSchTask* OR CommandLine:Grant\-ADIDNSPermission* OR CommandLine:Gupt\-Backdoor* OR CommandLine:HTTP\-Login* OR CommandLine:Install\-ServiceBinary* OR CommandLine:Install\-SSP* OR CommandLine:Invoke\-ACLScanner* OR CommandLine:Invoke\-ADRecon* OR CommandLine:Invoke\-ADSBackdoor* OR CommandLine:Invoke\-AgentSmith* OR CommandLine:Invoke\-AllChecks* OR CommandLine:Invoke\-ARPScan* OR CommandLine:Invoke\-AzureHound* OR CommandLine:Invoke\-BackdoorLNK* OR CommandLine:Invoke\-BadPotato* OR CommandLine:Invoke\-BetterSafetyKatz* OR CommandLine:Invoke\-BypassUAC* OR CommandLine:Invoke\-Carbuncle* OR CommandLine:Invoke\-Certify* OR CommandLine:Invoke\-ConPtyShell* OR CommandLine:Invoke\-CredentialInjection* OR CommandLine:Invoke\-DAFT* OR CommandLine:Invoke\-DCSync* OR CommandLine:Invoke\-DinvokeKatz* OR CommandLine:Invoke\-DllInjection* OR CommandLine:Invoke\-DNSUpdate* OR CommandLine:Invoke\-DNSExfiltrator* OR CommandLine:Invoke\-DomainPasswordSpray* OR CommandLine:Invoke\-DowngradeAccount* OR CommandLine:Invoke\-EgressCheck* OR CommandLine:Invoke\-Eyewitness* OR CommandLine:Invoke\-FakeLogonScreen* OR CommandLine:Invoke\-Farmer* OR CommandLine:Invoke\-Get\-RBCD\-Threaded* OR CommandLine:Invoke\-Gopher* OR CommandLine:Invoke\-Grouper* OR CommandLine:Invoke\-HandleKatz* OR CommandLine:Invoke\-ImpersonatedProcess* OR CommandLine:Invoke\-ImpersonateSystem* OR CommandLine:Invoke\-InteractiveSystemPowerShell* OR CommandLine:Invoke\-Internalmonologue* OR CommandLine:Invoke\-Inveigh* OR CommandLine:Invoke\-InveighRelay* OR CommandLine:Invoke\-KrbRelay* OR CommandLine:Invoke\-LdapSignCheck* OR CommandLine:Invoke\-Lockless* OR CommandLine:Invoke\-MalSCCM* OR CommandLine:Invoke\-Mimikatz* OR CommandLine:Invoke\-Mimikittenz* OR CommandLine:Invoke\-MITM6* OR CommandLine:Invoke\-NanoDump* OR CommandLine:Invoke\-NetRipper* OR CommandLine:Invoke\-Nightmare* OR CommandLine:Invoke\-NinjaCopy* OR CommandLine:Invoke\-OfficeScrape* OR CommandLine:Invoke\-OxidResolver* OR CommandLine:Invoke\-P0wnedshell* OR CommandLine:Invoke\-Paranoia* OR CommandLine:Invoke\-PortScan* OR CommandLine:Invoke\-PoshRatHttp* OR CommandLine:Invoke\-PostExfil* OR CommandLine:Invoke\-PowerDump* OR CommandLine:Invoke\-PowerDPAPI* OR CommandLine:Invoke\-PowerShellTCP* OR CommandLine:Invoke\-PowerShellWMI* OR CommandLine:Invoke\-PPLDump* OR CommandLine:Invoke\-PsExec* OR CommandLine:Invoke\-PSInject* OR CommandLine:Invoke\-PsUaCme* OR CommandLine:Invoke\-ReflectivePEInjection* OR CommandLine:Invoke\-ReverseDNSLookup* OR CommandLine:Invoke\-Rubeus* OR CommandLine:Invoke\-RunAs* OR CommandLine:Invoke\-SafetyKatz* OR CommandLine:Invoke\-SauronEye* OR CommandLine:Invoke\-SCShell* OR CommandLine:Invoke\-Seatbelt* OR CommandLine:Invoke\-ServiceAbuse* OR CommandLine:Invoke\-ShadowSpray* OR CommandLine:Invoke\-Sharp* OR CommandLine:Invoke\-Shellcode* OR CommandLine:Invoke\-SMBScanner* OR CommandLine:Invoke\-Snaffler* OR CommandLine:Invoke\-Spoolsample* OR CommandLine:Invoke\-SpraySinglePassword* OR CommandLine:Invoke\-SSHCommand* OR CommandLine:Invoke\-StandIn* OR CommandLine:Invoke\-StickyNotesExtract* OR CommandLine:Invoke\-SystemCommand* OR CommandLine:Invoke\-Tasksbackdoor* OR CommandLine:Invoke\-Tater* OR CommandLine:Invoke\-Thunderfox* OR CommandLine:Invoke\-ThunderStruck* OR CommandLine:Invoke\-TokenManipulation* OR CommandLine:Invoke\-Tokenvator* OR CommandLine:Invoke\-TotalExec* OR CommandLine:Invoke\-UrbanBishop* OR CommandLine:Invoke\-UserHunter* OR CommandLine:Invoke\-VoiceTroll* OR CommandLine:Invoke\-Whisker* OR CommandLine:Invoke\-WinEnum* OR CommandLine:Invoke\-winPEAS* OR CommandLine:Invoke\-WireTap* OR CommandLine:Invoke\-WmiCommand* OR CommandLine:Invoke\-WMIExec* OR CommandLine:Invoke\-WScriptBypassUAC* OR CommandLine:Invoke\-Zerologon* OR CommandLine:MailRaider* OR CommandLine:New\-ADIDNSNode* OR CommandLine:New\-DNSRecordArray* OR CommandLine:New\-HoneyHash* OR CommandLine:New\-InMemoryModule* OR CommandLine:New\-MachineAccount* OR CommandLine:New\-SOASerialNumberArray* OR CommandLine:Out\-Minidump* OR CommandLine:Port\-Scan* OR CommandLine:PowerBreach* OR CommandLine:powercat\ * OR CommandLine:PowerUp* OR CommandLine:PowerView* OR CommandLine:Remove\-ADIDNSNode* OR CommandLine:Remove\-MachineAccount* OR CommandLine:Remove\-Update* OR CommandLine:Rename\-ADIDNSNode* OR CommandLine:Revoke\-ADIDNSPermission* OR CommandLine:Set\-ADIDNSNode* OR CommandLine:Set\-MacAttribute* OR CommandLine:Set\-MachineAccountAttribute* OR CommandLine:Set\-Wallpaper* OR CommandLine:Show\-TargetScreen* OR CommandLine:Start\-CaptureServer* OR CommandLine:Start\-Dnscat2* OR CommandLine:Start\-WebcamRecorder* OR CommandLine:Veeam\-Get\-Creds* OR CommandLine:VolumeShadowCopyTools*